Summary created by Smart Answers AI
In summary:
- Macworld reports Apple has fully resolved a vulnerability in its Hide My Email feature that could expose users’ real addresses through bounced spam logs.
- The iCloud+ privacy tool creates anonymous email addresses for online sign-ups, but the flaw undermined this protection when spam emails bounced back to senders.
- Hidden addresses created before July 7, 2026 may still be compromised, and a class-action lawsuit has been filed over the feature’s unfulfilled privacy promises.
Good news, iCloud+ users. Following reports earlier this month that there was a flaw in Hide My Email that could potentially expose your address to the very people you were trying to hide it from, Apple has reportedly “fully resolved” the issue.
According to 404 Media, which broke the story on July 1, Apple patched the vulnerability just a few days after their report was published. The issue was originally discovered by Tyler Murphy of EasyOptOuts in June 2025 and reported to Apple, but in the year that followed it was never fixed, despite Apple’s assurances.
At the time of the report, Murphy and 404 Media didn’t divulge how the flaw could be exploited out of an abundance of caution, but they now report that the vulnerability was fairly low tech, failing to hide the main email address in spam email logs that were bounced back to the sender after they were rejected. Therefore, Murphy cautions that “any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs.”
Hide My Email is a feature of iCloud+ that allows users to create and reroute communication through an anonymous email address when signing up for online accounts. While users still receive the message in their iCloud Inbox, “If you choose the Hide My Email option, only the app or website you created the account with can use this unique email address to communicate with you,” according to an Apple support document.
In the time between the original report and the report of the fix, a class-action lawsuit was filed on behalf of iCloud+ users seeking damages incurred as a result of “having paid for a feature that did not have the promised quality and nature.”


